Dell PowerEdge R830 Integrated Remote Access Controller 8 Version 2.70.70.70 U - Page 145

Configuring iDRAC SSO login for Active Directory users

Page 145 highlights

4. Add the preceding SSO user (login user) to the device object. 5. Provide access privilege to Authenticated Users for accessing the created association object. Related concepts Adding iDRAC users and privileges to Active Directory Configuring iDRAC SSO login for Active Directory users Before configuring iDRAC for Active Directory SSO login, make sure that you have completed all the prerequisites. You can configure iDRAC for Active Directory SSO when you setup an user account based on Active Directory. Related concepts Prerequisites for Active Directory Single Sign-On or smart card login Related tasks Configuring Active Directory with Standard schema using iDRAC web interface Configuring Active Directory with Standard schema using RACADM Configuring Active Directory with Extended schema using iDRAC web interface Configuring Active Directory with Extended schema using RACADM Configuring iDRAC SSO login for Active Directory users using web interface To configure iDRAC for Active Directory SSO login: NOTE: For information about the options, see the iDRAC Online Help. 1. Verify whether the iDRAC DNS name matches the iDRAC Fully Qualified Domain Name. To do this, in iDRAC Web interface, go to Overview > iDRAC Settings > Network > Network and see the DNS Domain Name property. 2. While configuring Active Directory to setup a user account based on standard schema or extended schema, perform the following two additional steps to configure SSO: • Upload the keytab file on the Active Directory Configuration and Management Step 1 of 4 page. • Select Enable Single Sign-On option on the Active Directory Configuration and Management Step 2 of 4 page. Configuring iDRAC SSO login for Active Directory users using RACADM To enable SSO, complete the steps to configure Active Directory, and run the following command: racadm set iDRAC.ActiveDirectory.SSOEnable 1 Configuring iDRAC smart card login for local users To configure iDRAC local user for smart card login: 1. Upload the smart card user certificate and trusted CA certificate to iDRAC. 2. Enable smart card login. Related concepts Obtaining certificates Configuring iDRAC for Single Sign-On or smart card login 145

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298

4.
Add the preceding SSO user (login user) to the device object.
5.
Provide access privilege to
Authenticated Users
for accessing the created association object.
Related concepts
Adding iDRAC users and privileges to Active Directory
Configuring iDRAC SSO login for Active Directory
users
Before configuring iDRAC for Active Directory SSO login, make sure that you have completed all the prerequisites.
You can configure iDRAC for Active Directory SSO when you setup an user account based on Active Directory.
Related concepts
Prerequisites for Active Directory Single Sign-On or smart card login
Related tasks
Configuring Active Directory with Standard schema using iDRAC web interface
Configuring Active Directory with Standard schema using RACADM
Configuring Active Directory with Extended schema using iDRAC web interface
Configuring Active Directory with Extended schema using RACADM
Configuring iDRAC SSO login for Active Directory users
using web interface
To configure iDRAC for Active Directory SSO login:
NOTE:
For information about the options, see the
iDRAC Online Help
.
1.
Verify whether the iDRAC DNS name matches the iDRAC Fully Qualified Domain Name. To do this, in iDRAC Web interface, go to
Overview
>
iDRAC Settings
>
Network
>
Network
and see the
DNS Domain Name
property.
2.
While configuring Active Directory to setup a user account based on standard schema or extended schema, perform the following two
additional steps to configure SSO:
Upload the keytab file on the
Active Directory Configuration and Management Step 1 of 4
page.
Select
Enable Single Sign-On
option on the
Active Directory Configuration and Management Step 2 of 4
page.
Configuring iDRAC SSO login for Active Directory users
using RACADM
To enable SSO, complete the steps to configure Active Directory, and run the following command:
racadm set iDRAC.ActiveDirectory.SSOEnable 1
Configuring iDRAC smart card login for local users
To configure iDRAC local user for smart card login:
1.
Upload the smart card user certificate and trusted CA certificate to iDRAC.
2.
Enable smart card login.
Related concepts
Obtaining certificates
Configuring iDRAC for Single Sign-On or smart card login
145